Join our Newsletter — 33% off our NHI Course

Why do complex ERP platforms increase the risk of access drift and control gaps over time?

Complex ERP platforms create many users, integrations, custom roles, and service connections, which makes entitlement hygiene harder to sustain. As deployments expand across business units and environments, access can outgrow its original purpose. That is why governance, role review, and periodic recertification matter. Without them, excessive access and orphaned accounts become persistent operational risk.

Why This Matters for Security Teams

Complex ERP platforms concentrate finance, procurement, HR, logistics, and custom integrations into a single control plane, which means one entitlement mistake can reach far beyond a single application. Over time, access drift emerges when roles are reused, temporary exceptions become permanent, and service accounts outlive the workflows they were meant to support. NHIMG research shows that 97% of NHIs carry excessive privileges, a pattern that becomes more likely as ERP estates expand and change faster than review cycles can keep up, as discussed in the Ultimate Guide to NHIs – Key Challenges and Risks.

The security problem is not just too many users. ERP platforms accumulate custom roles, inherited permissions, middleware connections, background jobs, and API credentials that are often owned by different teams and governed inconsistently. That makes it easy for least privilege to erode silently, even when the original design was sound. Current guidance from the NIST Cybersecurity Framework 2.0 emphasises continuous governance, but ERP programs often treat access as a one-time project artifact instead of a living control. In practice, many security teams discover drift only after an audit exception, an orphaned integration, or an over-permissive service account has already been exploited.

How It Works in Practice

Access drift in ERP environments usually starts with legitimate change. A business unit requests a new report, an integration needs elevated permissions, or a support team creates a temporary exception to keep month-end processing moving. Those changes are rarely isolated. They get copied into cloned environments, reused in templates, or preserved because removing them would risk breaking downstream dependencies. Over time, the platform’s real access model diverges from its intended model.

Several mechanics make this worse:

  • Custom roles multiply faster than governance teams can review them.
  • So-called temporary access remains active because nobody owns the cleanup.
  • Service accounts and API keys persist after projects, migrations, or vendor changes.
  • Segregation-of-duties conflicts are waived for operational convenience and never revisited.

This is why periodic recertification alone is not enough. It helps identify stale entitlements, but it does not stop drift between review cycles. Better practice is to combine role engineering, entitlement baselining, and event-driven review triggers when ERP integrations change, users change function, or privileged workflows are modified. The Ultimate Guide to NHIs is useful here because ERP service accounts behave like other NHIs: they need ownership, rotation, and offboarding, not just a username in a directory. For control design, the NIST SP 800-53 Rev. 5 Security and Privacy Controls provides a practical baseline for access enforcement, review, and account management.

These controls tend to break down when ERP customisations are heavily outsourced, because ownership of inherited permissions becomes unclear and no team feels accountable for revoking them.

Common Variations and Edge Cases

Tighter ERP access control often increases operational overhead, requiring organisations to balance stronger governance against the need to keep core business processes running. That tradeoff is especially visible during mergers, multi-entity consolidations, and cloud migrations, where role models from different business units must be harmonised without disrupting payroll, procurement, or financial close.

Best practice is evolving for these environments. There is no universal standard for every ERP product and deployment pattern, but the direction is consistent: separate human access from machine access, assign explicit owners to every privileged role and service account, and review integrations as first-class identities rather than technical afterthoughts. NHIMG guidance on the Top 10 NHI Issues is especially relevant where ERP platforms rely on long-lived API keys, batch jobs, or middleware credentials.

Some environments need stricter handling than others. Shared admin teams, outsourced support, and cross-border operations can all complicate SoD enforcement, while legacy ERP modules may not support fine-grained revocation or just-in-time access. In those cases, security teams should prioritise compensating controls such as vaulting, short-lived credentials, transaction logging, and exception expiry dates. The lesson is simple: ERP risk rises when access becomes infrastructure, not governance. That is why drift should be treated as a lifecycle problem, not a permissions cleanup exercise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-03 Covers excessive or stale non-human access, common in ERP service accounts.
CSA MAESTRO Applies governance and runtime control to complex agent-like ERP workflows.
NIST CSF 2.0 PR.AC-4 Addresses access permissions management and least privilege in ERP environments.
NIST SP 800-53 Rev 5 AC-2 Account management is central to preventing orphaned ERP users and service accounts.
NIST AI RMF AI risk governance maps well to the need for continuous review of dynamic access paths.

Establish accountable oversight for changing ERP access, exceptions, and automated controls.